查看: 2340|回复: 9
收起左侧

[病毒样本] VirSCAN只有小红伞报可疑

[复制链接]
lomo
发表于 2008-3-29 10:49:57 | 显示全部楼层 |阅读模式

小红伞GUARD发出报警
经查看日志:
Virus or unwanted program 'HEUR/Malware [HEUR/Malware]'
detected in file 'C:\Program Files\Bang & Olufsen\BeoPlayer\MMHook.dll.
Action performed: Deny access

发现在B&O播放器安装目录下有个MMHook.dll的可疑文件

上传到VirSCAN分析,结果只有小红伞报。样本已经提交小红伞分析。
文件名称 :   MMHook.rar
文件大小 :   31660 byte
文件类型 :   RAR archive data, v1d, os
扫描结果 :   3%的杀软(1/36)报告发现病毒
时间 :   2008/03/29 10:35:36 (CST)
AntiVir 7.6.0.78 7.0.3.92 2008-03-28 HEUR/Malware 12.553

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
tanlimo
发表于 2008-3-29 10:54:29 | 显示全部楼层
ESS  avast! 全飘
秋叶濛濛
发表于 2008-3-29 10:59:50 | 显示全部楼层
红伞杀了
Begin scan in 'F:\Virus\MMHook.rar'
F:\Virus\MMHook.rar
  [0] Archive type: RAR
  --> MMHook.dll
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO]      The file was deleted!
lomo
 楼主| 发表于 2008-3-29 11:05:57 | 显示全部楼层
小红伞还在分析中
Subject:[#134060] Upload via Website - False positive suspicion   
Submitted on:29 Mar 2008 03:42 +0100  
Answer sent on:Pending...  


好像在我之前有人上传了同名的压缩包,不过有60多K,是我的两倍大。
只有小红伞报
不知道是不是误报
不过这个MM挂钩看起来不像是好东西
qigang
发表于 2008-3-29 19:09:17 | 显示全部楼层

2/0

rising20.37.52未知!
BING126
头像被屏蔽
发表于 2008-3-29 20:21:58 | 显示全部楼层
应该是误报?
lomo
 楼主| 发表于 2008-3-29 20:59:39 | 显示全部楼层
删了此dll
B&O播放器还可以正常使用
干脆把B&O播放器也卸载了
等待小红伞的结果
不过周末貌似休息


我上报小红伞的时候选的是可能误报
14206937
发表于 2008-3-29 21:26:10 | 显示全部楼层
相信应该是误报!
Exia 该用户已被删除
发表于 2008-3-31 17:11:30 | 显示全部楼层
The file 'MMHook.dll' has been determined to be 'MALWARE'. Our analysts discovered that the file is a Security Privacy Risk (SPR). In particular it means that it is a program that might possibly be able to affect the security of your system, might trigger activities you might not want or might violate your privacy. Detection will be added to our virus definition file (VDF) with one of the next updates. Please note that Avira's proactive heuristic detection module AHeAD detected this threat up front without the latest VDF update as: HEUR/Malware.
lomo
 楼主| 发表于 2008-3-31 17:17:04 | 显示全部楼层


We received the following archive files:


File ID Filename Size (Byte)Result
3802993 MMHook.rar30.92 KBOK

A listing of files contained inside archives alongside their results can be found below:
File ID Filename Size (Byte)Result
3802994 MMHook.dll 65.5 KB MALWARE


Please find a detailed report concerning each individual sample below:
FilenameResult
MMHook.dll MALWARE

The file 'MMHook.dll' has been determined to be 'MALWARE'.
Our analysts discovered that the file is a Security Privacy Risk (SPR). In particular it means that it is a program that might possibly be able to affect the security of your system, might trigger activities you might not want or might violate your privacy. Detection will be added to our virus definition file (VDF) with one of the next updates. Please note that Avira's proactive heuristic detection module AHeAD detected this threat up front without the latest VDF update as: HEUR/Malware.

应该是我最先上报的吧~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 03:45 , Processed in 0.131843 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表